Switch language한국어
Back to the list

GitHub investigates attack via malicious VS Code extension

TL;DR AI

Key summary

2 min read
  1. GitHub is investigating unauthorized access to its internal repositories, likely triggered by a poisoned Visual Studio Code extension.

  2. The company says there is no evidence customer data or private repositories were affected, and it is reviewing logs and rotating credentials.

  3. Reports claim attackers may have accessed thousands of repositories and could be tied to the Shai-Hulud malware campaign, but that has not been confirmed.

  4. The incident raises concerns about supply-chain security, exposed code and credentials, and the risk of follow-on attacks.

Read the original